critical · CVSS v3 9.8 · CVSS v4 7.7
CVE-2026-82928
mH-DEVELOPER smart home module contains a hardcoded SSH public key that allows root login via key authentication, enabling attackers with th
Overview
mH-DEVELOPER smart home module contains a hardcoded SSH public key that allows root login via key authentication, enabling attackers with the matching private key to gain full system compromise. The key persists across factory resets and cannot be removed without remounting the filesystem. This backdoor poses a critical risk to device security.
Description
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30
Impact
Confidentiality, integrity, and availability are compromised as attackers can obtain root access, effectively taking control of the device. Device owners, homeowners, and any users of the affected smart home module are impacted. Defenders should treat all affected devices as compromised until patched.
Remediation
Update the firmware to version 3.0.30 or later. If an update is not possible, disable SSH root login by editing /etc/ssh/sshd_config to set PermitRootLogin no and remove the hardcoded key from /root/.ssh/authorized_keys after remounting the filesystem as read‑write. Reboot the device to apply changes and monitor logs for unauthorized SSH activity.
Risk context
The vulnerability has a critical severity with a CVSS v3 score of 9.8 and no EPSS data available, indicating a high likelihood of exploitation. Immediate action is required to prevent potential full system compromise.
Affected products
- mH-DEVELOPER Smart Home Module
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 9.8
- CVSS v4
- 7.7
- EPSS
- —